Back to magazine

Legal

GDPR in the salon: what is actually required

Data protection sounds like bureaucracy but is manageable in a salon once you know the basics. This text is not legal advice but gives orientation.

Which data you actually process:

Name, contact details, appointments, treatment notes, and in beauty also health information (allergies, medication). The latter counts as especially sensitive and needs explicit consent.

Consent means active and freely given:

A pre-ticked box is not enough. Newsletters need genuine opt-in, ideally with a confirmation email (double opt-in). For before-and-after photos on Instagram you need separate written consent – the treatment itself does not cover it.

Storing and deleting:

Data is kept as long as it is needed or legal retention periods require (invoices: ten years). After that it is deleted. Clients have the right to request information and demand erasure.

In practice:

A record of processing activities, a privacy policy on the website, contracts with providers who process data for you (booking software, newsletter tools), and lockable cabinets for paper files. That is the core.

Remember:

The most common mistake is not missing paperwork but the Instagram photo without consent. Ask – in writing, once, kindly.

Ready to make your business visible?

Start free